


Perceptive Security
SOC/SIEM Consultancy

Improper Restriction of XML External Entity Reference vulnerability in XMLUtils.java in Slovensko.Digital Autogram allows remote unauthenticated attacker to con…
Published:
18 March 2026 at 23:00:00
Alert date:
19 March 2026 at 13:02:35
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
CVE-2026-3511 is an XML External Entity (XXE) vulnerability in XMLUtils.java of Slovensko.Digital Autogram application. The vulnerability allows remote unauthenticated attackers to conduct Server Side Request Forgery (SSRF) attacks and gain unauthorized access to local files on the filesystem. Exploitation requires victims to visit a malicious website that sends specially crafted XML documents to the /sign endpoint of the local HTTP server. The vulnerability affects the XML processing functionality and can lead to sensitive file disclosure and internal network reconnaissance through SSRF attacks.
Technical details
Mitigation steps:
Affected products:
Slovensko.Digital Autogram
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-3511
https://blog.binary.house/2026/03/pripadova-studia-ako-sme-s-claude-code.html
https://github.com/slovensko-digital/autogram/releases/tag/v2.7.2
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
